Dimov Audit
An operations team reviewing a printed controls matrix

SOC 1 audit firm for your customers' auditors

If a customer's auditor has asked for your SOC 1 compliance, the document they need is your SOC 1 report. Send us that request, and we will read it before we scope your SOC 1 audit.

What is a SOC 1 report

  • Your customers' auditors use it when they audit your customers' financial statements, to judge the controls you run on their behalf.
  • A CPA examines your controls, not your own financial statements, and gives an opinion on them.
  • The CPA follows AT-C section 320 of SSAE 18, the AICPA standard, which is why some customers call it an SSAE 18 audit.

Who needs a SOC 1 report

A customer's auditor asks for a SOC 1 report when your company processes transactions, or holds records, that the customer reports in its own financial statements. Four common cases:

  • Payroll processors

    You calculate and pay wages that your customers record as expense.

  • Loan and mortgage servicers

    You post borrower payments to accounts your lender customers report.

  • Claims and benefits administrators

    You adjudicate and pay claims from funds your customers hold.

  • Hosting and software providers

    You run the accounting or transaction system your customers rely on for their books.

SOC 1 Type 1 vs Type 2

In a SOC 1 Type 1, the CPA reports on the design of your controls as of one date. In a SOC 1 Type 2, the CPA also reports on how they operated through a period and lists each test and its result. Under the AICPA's SOC 1 guide, the period a Type 2 covers should overlap a substantial portion of your customer's financial statement period, so ask the customer's auditor for the dates it needs.
What each SOC 1 type coversIllustrative timelines, not to scaleType 1ONE DATEOpinion on your description and the design of your controlsTests listed: noType 2A SPECIFIED PERIODOpinion on your description, the design of your controls and how they operated through the periodTests and results listed: yes
Ask your customer's auditor which type and which period it needs before you book the work.

The SOC 1 audit process

  1. Step 01

    Scope

    We agree which services, locations and systems the report covers, which type you need and, for a Type 2, the period.

  2. Step 02

    Preparation

    Your management prepares the report materials and gathers the evidence we will need before testing starts.

  3. Step 03

    Testing

    We evaluate the design of your controls and, for a Type 2, test how they operated by sampling transactions and evidence.

  4. Step 04

    Report

    We issue the report with our opinion, for you to share with your customers and their auditors.

SOC 1 requirements your team prepares

  • System description

    Your management describes the services, the processes and systems behind them and the controls in place, then signs a written assertion about the description and the controls.
  • Control objectives

    In your SOC 1 control objectives, your management states what each group of controls is meant to achieve against a risk, such as stopping an unauthorized pay-rate change. The CPA checks that the objectives are reasonable.
  • Vendors that run part of the service

    If a data center or other vendor runs part of it, your management either includes that vendor's controls in the description or carves them out and says so.

Scope your first SOC 1 with a CPA

Send the request from your customer's auditor, the services it names and the vendors that run part of them. We will tell you which type your customer needs and what the scope includes before you commit.

An operations manager and an auditor talking through scope

Can a SOC 1 audit fail

Under the AICPA attestation standards, the CPA gives an opinion rather than a pass or fail grade:
Unmodified
The CPA found your description fairly presented and your controls suitably designed, and in a Type 2, operating effectively.
Qualified
The CPA found a material problem confined to part of the description or the controls, and says so in the opinion.
Adverse
The CPA found material problems that run through the description or the controls as a whole.
Disclaimer
The CPA could not get enough evidence and states that no opinion is given.

Ask to see your draft description early, while there is still time to fix it.

What sets the cost of a SOC 1 audit

We quote the work against its scope:

  • Type and period

    We test more for a Type 2, and more again across a longer period.

  • Control objectives

    We test the controls under each objective you set, so we price by how many you set.

  • Vendors

    We test a vendor's controls only when your report includes them rather than carving them out.

  • Locations and systems

    We price by how many locations and systems run the controls in scope.

Tell us whether this is your first SOC 1 or a renewal when you ask for a quote.

  • 500+

    completed audits

  • 50

    states served

  • AICPA

    peer-reviewed firm

  • 16+

    years in audit

Firm figures as of September 2026, from the Dimov Audit homepage.

George Dimov on a complaint he hears about accounting firms:

This is one of the biggest complaints that we see in professional services: people hire an accountant and that accountant is thereafter unreachable over the phone or over email.
George Dimov, CPA

Audit and attestation services

Treat the information as general, and ask a CPA to read your customer's request before you commit to a report.

Get a quote for your SOC 1

Send a short description of your service and the request from your customer's auditor. We will scope the report and quote it before you sign.

Contact

Connect with Dimov Audit

Our dedicated team is ready to assist you on your path to financial success.

New York Office

24 Mercer St, 2nd Floor, Suite 214
New York, NY 10013
United States

Reviewed by George Dimov, CPA. Dimov Audit performs attestation work under AICPA standards. George brings 20+ years of accounting and consulting experience. Profile